GDPR (EU) 2016/679

EU regulation on the protection of personal data. Any organisation processing personal data of people in the EU.

4 controls supported. References are articles of the regulation.

Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

  • Control
    • 32.1.bConfidentiality
    • 32.1.cTimely restoration of availability
    How we help
    Keeps systems that process personal data available and restorable after an incident in the primary site.
    Evidence you get
    Recovery test reports for your Article 32 documentation.
  • Mapping under review

    Control
    • 32.1.aPseudonymisation and encryption
    • 32.1.cTimely restoration of availability
    How we help
    Encrypted backups that let you restore access to personal data in a timely manner.
    Evidence you get
    Encryption and restore test records.
  • Mapping under review

    Control
    • 32.1.bConfidentiality
    • 32.1.cTimely restoration of availability
    How we help
    Automatic failover, and on the Enterprise plan a second authoritative DNS network, help keep services that process personal data available, and restore access quickly when a primary service fails.
    Evidence you get
    NS delegation showing both networks (Enterprise), failover configuration and event history.
  • Mapping under review

    Control
    • art.33Breach notification
    How we help
    Lets you establish what happened, and to which data, within the 72-hour notification window.
    Evidence you get
    Log retention configuration, investigation runbook.
  • Mapping under review

    Control
    • 32.1.bConfidentiality
    How we help
    Keeps applications that process personal data available and protected against attack.
    Evidence you get
    Threat reports for your Article 32 documentation.
  • Control
    • 32.1.bConfidentiality
    How we help
    Only authorised people reach personal data, and DLP blocks it from leaving through unapproved channels.
    Evidence you get
    Access policy export, DLP incident reports.

Tell us what you are preparing for

We reply with the controls we can cover, what stays on your side, and a realistic timeline.

Where are you now?